MALICIOUS — dabezirijufon-lafabipadafipiz-radeko-mevubajofok.pdf
MALICIOUS — dabezirijufon-lafabipadafipiz-radeko-mevubajofok.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
153475488d28cfc7930b3df8c087c14926ffc0795e62a96bc254d65266952447 - SHA-1:
797807bcc9a865ef6be32ebf150af3917d5114f9 - MD5:
c3be817b92071a8dee58e2237b692e4d - ssdeep:
768:YgGzpDZtpEPIZcFh3fPJnQljBX6kJSjqLyIO1ZNYZ1vxTQuSucePwJHi:1GFfptBwUyX1/YbvxTQugQwJHi - TLSH:
T1F0317CF350EBED8C7E875B836CA61255608AD3487237E790548C7A2CC5BC6BD6F10922 - Submitted as: dabezirijufon-lafabipadafipiz-radeko-mevubajofok.pdf
- File type: pdf · Size: 41269 bytes
- Verdict: malicious (75/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/68f148888da839.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=hp%20a%20btu, https://uploads.strikinglycdn.com/files/03293fc6-46c4-42e6-bb33-7278154f103f/vixopiwukerika.pdf, https://uploads.strikinglycdn.com/files/b3ff8ba5-535c-4006-9aab-dd8c7d821ffd/wiradiri.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=hp%20a%20btu
- https://uploads.strikinglycdn.com/files/03293fc6-46c4-42e6-bb33-7278154f103f/vixopiwukerika.pdf
- https://uploads.strikinglycdn.com/files/b3ff8ba5-535c-4006-9aab-dd8c7d821ffd/wiradiri.pdf
- https://uploads.strikinglycdn.com/files/6974369f-99f1-497a-aa1f-6c36748ec796/90978137738.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/3a6af17.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/maven-dovuroripugeto.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/68f148888da839.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/6116436.pdf
- https://uploads.strikinglycdn.com/files/c9ffe834-ebce-4398-9b87-c477ee0d98f0/kotojagegatodubasinit.pdf
- https://uploads.strikinglycdn.com/files/a3ad87b6-3769-4bb7-bbd6-87912b78b0b0/18047691440.pdf
- https://uploads.strikinglycdn.com/files/b8772c90-c86f-4574-80e4-da1062b8e5fe/69876075931.pdf
- https://uploads.strikinglycdn.com/files/56a4d122-17c5-41ea-9a84-185c38ffe0f5/58271386843.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/xelegaradawode.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/vixezuxapa-texewenagig-dewuxukazavi.pdf
- https://cdn.shopify.com/s/files/1/0431/6564/6999/files/dujuveliwegetafogumi.pdf
- https://cdn.shopify.com/s/files/1/0496/6304/9879/files/renabep.pdf
- https://cdn.shopify.com/s/files/1/0431/9418/7933/files/fugakafuxes.pdf
- https://cdn.shopify.com/s/files/1/0499/9177/8454/files/dodosenonefabuseko.pdf
- https://cdn.shopify.com/s/files/1/0428/0621/4819/files/tufamavuk.pdf
- https://cdn.shopify.com/s/files/1/0496/0826/1784/files/maths_question_bank_for_class_8.pdf
- https://cdn.shopify.com/s/files/1/0432/8990/3264/files/bully_english_5_answers_ps2.pdf
- https://cdn.shopify.com/s/files/1/0478/0710/3143/files/72452238788.pdf
- https://cdn.shopify.com/s/files/1/0431/6721/9878/files/dig_a_hole_in_the_meadow_gangstagrass.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- vuzevarezevarot.weebly.com
- babinekisifuve.weebly.com
- jamuseramomuf.weebly.com
- xebikazogede.weebly.com
- jawasolasazilem.weebly.com
- mamunazeve.weebly.com
- tudupumodowi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report